Privacy Policy
CloudStream operates the cloudstream.pro website and the CloudStream TV media-player applications. CloudStream does not host, sell, or distribute TV channels, movies, or series. You supply your own legally obtained playlist credentials (M3U playlist URL or Xtream Codes server details). This policy describes what our website, apps, and related services process, how that information is used, and the choices you have.
1. Who we are
The data controller for CloudStream TV app licensing, activation, and phone-to-TV pairing services is CloudStream, operating at https://cloudstream.pro/. For privacy questions contact support@cloudstream.pro.
2. Information we collect
2.1 Data stored on your device (local only)
Unless you choose to back up or share it, the following stays on your Android device in app storage (Room database, DataStore, or encrypted preferences):
- Provider configuration — names, server URLs, M3U playlist URLs, and Xtream/Stalker usernames. Passwords are encrypted with Android Keystore (
CredentialCrypto). - Catalog cache — channel, movie, series, episode, category, and EPG metadata fetched from your IPTV provider.
- Playback data — watch history, resume positions, favorites, search history, hidden channels/categories, and player compatibility notes.
- App preferences — language, layout, guide settings, parental-control level, and player options. Parental PINs are stored as salted hashes, not plain text.
- License state — trial start time, activation plan, activation code, optional customer email, and server-validated access flags.
- Downloads & recordings — metadata and files you explicitly save to device storage.
- Crash diagnostics — if the app crashes, a local text report (device model, app version, stack trace with URLs and credentials redacted) is saved on-device. It is not uploaded automatically. You may view, share, or delete it in Settings.
Android backup is enabled (android:allowBackup="true"). When your device backup is on, the app can include your provider database, preferences, and settings in Google’s device backup and device-to-device transfer (see backup_rules.xml). In-place app updates always keep your playlists and settings. Uninstalling the app still removes local data unless you exported a backup file, used Google Drive backup, or restore from a device backup.
2.2 Data sent to CloudStream servers
When you use CloudStream activation, subscription sync, or phone pairing, the app contacts https://cloudstream.pro/customers/ and may transmit:
| Data | Purpose | When sent |
|---|---|---|
Android device ID (ANDROID_ID) or registered device ID | License binding, pairing, playlist proxy | Activation, status sync, pairing |
| MAC address (hardware if available, otherwise a deterministic value derived from device ID) | Device identification for admin support and playlist access | Activation, status sync, pairing |
| Hardware fingerprint (hashed device characteristics: model, board, screen size, SDK) | TV Device ID display and admin lookup | Status sync |
| Device model / device name | Support and admin dashboard | Status sync, pairing session |
| Activation code | Validate app license or subscription plan | When you enter a code |
| Pairing token | Link your phone browser session to the TV | QR / phone pairing flow |
| Email address | Associate your CloudStream customer account | Returned by server after successful activation (if applicable) |
We do not receive your IPTV stream content. Playlist credentials you add may be submitted to your provider’s servers or, for CloudStream-managed customers, to our customer API solely to retrieve your assigned playlist.
2.3 Data sent to your IPTV provider
To play content, the app connects directly to servers and URLs you configure (Xtream API, M3U, Stalker portal, EPG sources, etc.) and sends credentials required by that provider. CloudStream does not control those third-party services. Review your provider’s privacy policy for their practices.
2.4 Google services and advertising
- Google Sign-In & Drive backup (optional) — If you sign in, Google processes your account per Google’s Privacy Policy. The app uploads a configuration backup (providers without passwords, favorites, preferences) to your Google Drive
appDataFolder, invisible in the normal Drive UI. - Google Cast (optional) — If you cast to a Chromecast device, Google Cast framework may process playback metadata per Google’s policies.
- Google AdMob (Google Play mobile build) — The Google Play phone/tablet version may show an adaptive banner and an occasional interstitial before eligible video-on-demand playback while the app has a free or trial entitlement. Ads are not initialized on Android TV devices, direct-download APK builds, or for users whose lifetime activation is recognized by the app.
- Google User Messaging Platform (UMP) — The app uses Google’s consent SDK to request and store advertising privacy choices where required, including European consent choices and supported US state privacy choices. A privacy-options entry is available in the app when Google requires it.
For advertising, Google and its partners may process information such as the Android Advertising ID when available and permitted, IP address, approximate location derived from network information, device and app information, ad interactions, diagnostics, and consent signals. Google may use this information to provide personalized, non-personalized, or limited ads as permitted by your choices and applicable law. See How Google uses information from sites or apps that use its services and Google’s Privacy Policy.
The app waits for UMP to confirm whether ads may be requested. If Google reports that ads cannot be requested, CloudStream does not initialize or request an ad. Refusing advertising consent does not disable the core media-player functions. Your seven-day trial and activation status are separate from your advertising-consent choice.
2.5 Website use, cookies, and Google AdSense
When you visit cloudstream.pro, our hosting and security providers may process your IP address, browser and device type, requested URL, referring page, timestamps, approximate network location, and security events. This information is used to deliver pages, prevent abuse, investigate errors, and maintain the website. Checkout, account, activation, and pairing pages may also use essential session storage or cookies required to complete the function you request.
If Google AdSense is enabled after the website is approved, Google and participating third-party vendors may use cookies, web beacons, IP addresses, device or browser identifiers, consent signals, and ad interactions to deliver, limit, secure, and measure advertising on eligible public content pages. Depending on your location and choices, ads may be personalized, non-personalized, or limited. Google explains this processing in How Google uses information from sites or apps that use its services and its Advertising technologies notice.
Where required, we use a Google-certified consent management platform for website advertising. Visitors in the European Economic Area, United Kingdom, and Switzerland can accept, reject, or manage eligible advertising purposes before personalized ads are requested. Supported US-state visitors may receive additional privacy choices. You can also review Google advertising controls at My Ad Center. More information is available in our Cookie Policy.
Google ads are not intended for checkout, account-login, device-pairing, error, or other low-content utility screens.
2.6 Optional metadata enrichment
When information supplied by your playlist is missing, the app may send the content type, title, year, and app language to the CloudStream metadata endpoint. Our server forwards that lookup to The Movie Database (TMDB) and returns available artwork and descriptive metadata. Playlist credentials, device identifiers, and viewing history are not included in this lookup. Results may be cached on our server for performance and abuse prevention.
This product uses the TMDB API but is not endorsed or certified by TMDB.
2.7 What we do not collect
- No Firebase Analytics or Firebase Crashlytics. Google AdMob and UMP are used only as described in section 2.4.
- No precise GPS location, contacts, SMS, photos, microphone, or calendar access.
- CloudStream does not sell personal data to data brokers.
3. How we use information
- Provide and maintain the media player and TV guide features.
- Validate app licenses, trials, and CloudStream customer subscriptions.
- Enable phone-to-TV pairing and customer playlist delivery.
- Remember your preferences, favorites, and playback position on-device.
- Request advertising consent and show eligible ads in the ad-supported Google Play mobile build.
- Deliver and secure the cloudstream.pro website and, after approval, show Google AdSense ads on eligible public content pages in accordance with visitor choices.
- Fill missing movie or series artwork and descriptive metadata through TMDB.
- Improve stability when you voluntarily share a crash report.
4. Legal bases (EEA/UK/Switzerland users)
We process data based on: (a) performance of a contract — providing the app and your subscription; (b) legitimate interests — fraud prevention, device binding, service security, and non-personal metadata lookup; and (c) consent — optional Google Sign-In/Drive backup, notification permission, and advertising storage, access, or personalization where consent is required. Google and its advertising partners identify their applicable purposes and legal bases in the consent form. You may refuse or withdraw advertising consent without losing the app’s core media-player functions; trial expiry and license activation remain separate.
5. Data retention
- On-device data — retained until you delete it in the app, clear app storage, or uninstall.
- CloudStream server records — retained for the life of your customer account and as needed for billing, support, and legal compliance, then deleted or anonymized per our internal retention schedule.
- Google Drive backups — retained until you delete them or uninstall the app (Google may remove
appDataFolderdata on uninstall). - Advertising and consent data — retained by Google and its partners according to their own policies and the consent choices available to you.
- Website security logs — retained only as long as reasonably necessary for hosting, diagnostics, abuse prevention, and legal compliance.
- Metadata lookup cache — TMDB lookup results may be cached by CloudStream only as long as reasonably needed for performance, reliability, and abuse prevention.
6. Sharing and disclosure
We may share data with:
- Your IPTV provider — to authenticate and deliver streams you request.
- Google and participating advertising partners — for Sign-In, Drive backup, Cast, AdMob, AdSense, and consent management as applicable to the feature, page, location, and your choices.
- TMDB — content title, type, year, and language for optional metadata enrichment when playlist information is missing.
- Service providers — hosting and infrastructure for cloudstream.pro, under confidentiality obligations.
- Authorities — when required by law or to protect rights and safety.
CloudStream does not sell personal data to data brokers. Advertising-related processing and sharing by Google and participating partners occurs only as described above and subject to the privacy choices presented through UMP.
7. Security
Provider passwords are encrypted at rest. Parental PINs are hashed with PBKDF2. Network traffic to CloudStream uses HTTPS. The app allows cleartext HTTP where required by user-supplied IPTV providers (usesCleartextTraffic). You are responsible for using lawful providers and secure credentials.
8. Children’s privacy
CloudStream TV is not directed at children under 13. The app includes optional parental controls, but users may access third-party streams with mature themes depending on their IPTV subscription. Parents and guardians are responsible for provider choice and PIN configuration.
9. International transfers
CloudStream servers may be located outside your country. Where required, we use appropriate safeguards for cross-border transfers.
10. Your rights and choices
- Access / export — export app settings and provider list via Settings → Backup (passwords excluded from export).
- Deletion — remove providers, clear history, delete crash reports, sign out of Google Drive, or uninstall the app. Contact us to request deletion of CloudStream account data.
- Advertising privacy choices — use Settings → Ad privacy options when that entry is available to review or change your choices. Refusing advertising consent does not disable the core player. Depending on Google’s eligibility decision, the app may request non-personalized or limited ads, or request no ads.
- Other Google services — do not use Google Sign-In, Drive backup, or Cast if you prefer not to interact with those optional services.
- Notifications — disable in Android system settings.
- EEA/UK/Switzerland rights — you may have rights to access, rectify, erase, restrict, object, and port data, and to lodge a complaint with your supervisory authority.
11. Google Play distribution
Play Store builds disable sideloaded app updates, third-party plugin APK installation, and offline license bypass codes. Updates are delivered through Google Play. Self-update checks contact cloudstream.pro or GitHub only in non-Play builds. The Google Play mobile build can operate in an ad-supported state during an eligible free or trial entitlement; recognized lifetime activations are ad-free. Google Play Android TV devices do not initialize the mobile advertising SDK.
12. Copyright and user responsibility
CloudStream TV is a player only. It does not bundle copyrighted channels, logos, or media. You must have lawful rights to any playlist or stream you add. CloudStream is not responsible for unauthorized content accessed through user-supplied credentials.
13. Changes to this policy
We may update this policy. Material changes will be posted at this URL with a revised effective date. Continued use after changes constitutes acceptance.
14. Contact
CloudStream
Website: cloudstream.pro
Email: support@cloudstream.pro
WhatsApp support: +44 7537 105407
Related documents: Terms of Use · Cookie Policy · Copyright & Takedown Policy · About CloudStream · CloudStream TV app page